CVE Vulnerabilities

CVE-2007-1254

Published: Mar 03, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SQL injection vulnerability in part.userprofile.php in Connectix Boards 0.7 and earlier allows remote authenticated users to execute arbitrary SQL commands and obtain privileges via the p_skin parameter to index.php.

Affected Software

NameVendorStart VersionEnd Version
Connectix_boardsConnectix0.4 (including)0.4 (including)
Connectix_boardsConnectix0.4.1 (including)0.4.1 (including)
Connectix_boardsConnectix0.4.2 (including)0.4.2 (including)
Connectix_boardsConnectix0.4.3 (including)0.4.3 (including)
Connectix_boardsConnectix0.4.4 (including)0.4.4 (including)
Connectix_boardsConnectix0.5 (including)0.5 (including)
Connectix_boardsConnectix0.5.1 (including)0.5.1 (including)
Connectix_boardsConnectix0.5.2 (including)0.5.2 (including)
Connectix_boardsConnectix0.5.3 (including)0.5.3 (including)
Connectix_boardsConnectix0.5.4 (including)0.5.4 (including)
Connectix_boardsConnectix0.5.5 (including)0.5.5 (including)
Connectix_boardsConnectix0.6 (including)0.6 (including)
Connectix_boardsConnectix0.6.1 (including)0.6.1 (including)
Connectix_boardsConnectix0.7 (including)0.7 (including)

References